Microsoft Copilot security directory

Workday

Published by Microsoft

High risk

Use the Workday connector to invoke Workday SOAP and REST services for performing various on-demand business management services.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 11 tools or capabilities.

  • Execute RaaS operation
  • Execute SOAP operation
  • Get feedback templates (Preview)
  • Get my worker profile (Preview)
  • Get supervisory organizations managed by worker (Preview)
  • Get worker direct reports (Preview)
  • Get worker inbox tasks (Preview)
  • Get worker pay slips (Preview)
  • Request feedback on worker (Preview)
  • Search workers (Preview)
  • Transfer employee (Preview)

The interactive security report will load automatically.